fix(auth): SubjectTokenProviderError drops response and duplicates error message in workload identity providers
I maintainer di solito rispondono entro 1 giorno
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 86/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- python
- Ambito
- authentication
Direzione di ricerca
Inizia in src/openai/auth/_workload.py e analizza la gestione delle eccezioni in k8s_service_account_token_provider, azure_managed_identity_token_provider e gcp_id_token_provider. Riproduci il problema con la risposta HTTP 500 simulata descritta sopra, quindi verifica che SubjectTokenProviderError conservi la risposta ed eviti i messaggi duplicati e il concatenamento ridondante delle eccezioni.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Confirm this is an issue with the Python library and not an underlying OpenAI API
- This is an issue with the Python library
Describe the bug
In src/openai/auth/_workload.py, the built-in workload identity subject token providers (azure_managed_identity_token_provider(), gcp_id_token_provider(), and k8s_service_account_token_provider()) catch their own intentionally raised SubjectTokenProviderError exceptions inside generic except Exception as e: blocks.
This leads to two issues:
- Lost
responseproperty:SubjectTokenProviderErrordefines aresponse: httpx2.Response | Noneattribute. The provider functions explicitly passresponse=responsewhen the metadata server returns an error status (response.is_error) or an empty body. However, the outerexcept Exception as e:intercepts this error (asSubjectTokenProviderErrorinherits fromOpenAIError->Exception) and instantiates a brand newSubjectTokenProviderError(...)without passingresponse, settingerr.responsetoNone. Callers attempting to inspecterr.responsefor headers, status codes, or error details receiveNone. - Duplicated error message prefixes: The re-wrapped exception message duplicates the prefix (e.g.
"Failed to fetch Azure subject token from IMDS: Failed to fetch Azure subject token from IMDS: HTTP 500"). - Redundant exception nesting: A
SubjectTokenProviderErroris chained as the__cause__of an identicalSubjectTokenProviderError.
To Reproduce
Steps:
- Initialize
azure_managed_identity_token_provider()orgcp_id_token_provider()with anhttp_clientmock returning an HTTP 500 (or non-200) error. - Call
provider["get_token"](). - Catch
SubjectTokenProviderErrorand inspecterr.responseandstr(err).
Code snippets
import httpx2
from openai.auth._workload import azure_managed_identity_token_provider
from openai._exceptions import SubjectTokenProviderError
mock_client = httpx2.Client(
transport=httpx2.MockTransport(lambda req: httpx2.Response(500, text="Internal Server Error"))
)
provider = azure_managed_identity_token_provider(http_client=mock_client)
try:
provider["get_token"]()
except SubjectTokenProviderError as err:
print(f"err.response is: {err.response}") # Actual: None | Expected: <Response [500]>
print(f"Error message: {err}")
print(f"err.__cause__: {repr(err.__cause__)}")
Actual Output:
err.response is: None
Error message: Failed to fetch Azure subject token from IMDS: Failed to fetch Azure subject token from IMDS: HTTP 500
err.__cause__: SubjectTokenProviderError('Failed to fetch Azure subject token from IMDS: HTTP 500')
Expected Output:
err.response should retain the <Response [500 Internal Server Error]> object attached when the initial SubjectTokenProviderError was raised, and the error message should not contain duplicated prefixes.
Proposed fix
In src/openai/auth/_workload.py:
In k8s_service_account_token_provider, azure_managed_identity_token_provider, and gcp_id_token_provider, re-raise SubjectTokenProviderError before the generic except Exception block:
except SubjectTokenProviderError:
raise
except Exception as e:
raise SubjectTokenProviderError(f"...: {e}") from e
OS
All platforms (cross-platform library error handling)
Python version
Python 3.10+
Library version
openai v1.x / latest main
- Lingua principale
- Python
- Stelle
- 31.8k
- Fork
- 7.3k
- Merge medio
- 1g 3h
- PR unite (30g)
- 131
Preparare l'ambiente
Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di openai/openai-python
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
openai/openai-python#4022 · 19 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
Querystring drops explicit empty-string scalar valuesForse già presa @sylvesterkaczmarek l’ha presa 30 giorni fa. Apertasdk-breaking-change v4
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
openai/openai-python#3837 ·
I maintainer di solito rispondono entro 1 giorno
-
Define + export `ServiceTiers` string literalForse già presa @SparshGarg999 l’ha presa 57 giorni fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
openai/openai-python#3556 · 3 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
Empty OPENAI_BASE_URL prevents fallback to default API endpointForse già presa @Sehastrajit-S l’ha presa 23 giorni fa. Apertabug
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
openai/openai-python#2927 · 6 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
Realtime API Pydantic Models incomplete for RealtimeResponseStatus typeForse già presa @LuminaX-alt l’ha presa 437 giorni fa. Apertabug openapi
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
openai/openai-python#2502 · 7 commenti ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di openai/openai-python
Issue simili
-
area: desktop area: website priority: P2 type: feature
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
appandflow/stim#3411 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 Meno di un'ora Idoneità per principianti 88/100
baptistehamon/lsapy#185 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
PolicyEngine/policyengine-us#10073 ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
syedhamidali/radarx#277 ·
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
Arekkazu/sgpmp-backend#549 ·
I maintainer di solito rispondono entro 1 giorno